Hawi Agents — Cookie Policy
Effective 23 August 2026
Last Updated: 23 August 2026
This Cookie Policy explains how Hawi Inc, trading as Hawi Agents (“Hawi”, “Hawi Agents”, “we”, “us”, or “our”) uses cookies and similar technologies when you visit, access or use our websites, web applications, dashboards, account areas, Marketplace, developer services and other online services that link to this Cookie Policy (collectively, the “Services”).
This Cookie Policy should be read together with our:
- Privacy Policy;
- Terms and Conditions;
- and, where applicable, Data Processing Agreement and other product-specific terms.
This Policy applies to cookies and other technologies that store information on, or access information from, your browser, computer, smartphone, tablet or other device.
Company details to complete before publication:
- Legal entity: Hawi Inc
- Trading name: Hawi Agents
- Registered office: [INSERT REGISTERED ADDRESS]
- Company number: [INSERT COMPANY NUMBER]
- Website: [INSERT FINAL PRODUCTION DOMAIN]
- Privacy email: [INSERT PRIVACY EMAIL]
- Support email: [INSERT SUPPORT EMAIL]
1. What Are Cookies?
Cookies are small pieces of information that a website places on or accesses from your device.
Cookies can allow a website to recognise a particular browser or device and may be used for purposes such as:
- keeping you signed in;
- maintaining a secure session;
- remembering your settings;
- remembering cookie choices;
- protecting against fraud;
- processing payments;
- maintaining application state;
- measuring how a website is used;
- identifying technical problems;
- and, where you have consented, providing analytics, personalisation or advertising functionality.
Cookies may contain a randomly generated identifier, session identifier, preference or other technical information.
Cookies do not necessarily contain your name or directly identify you. However, an identifier stored in a cookie may become personal data when it can be associated with an identifiable individual.
2. This Policy Also Covers Similar Technologies
The rules applying to cookies may also apply to other technologies that store or access information on a user's device.
Accordingly, references to “cookies” in this Policy also include, where applicable:
- local storage;
- session storage;
- browser storage;
- software development kits;
- pixels;
- tracking pixels;
- scripts;
- tags;
- web beacons;
- embedded content technologies;
- device identifiers;
- link-decoration technologies;
- navigational tracking;
- device recognition technologies;
- and similar storage or access mechanisms.
Hawi does not treat a technology as outside this Policy merely because it is technically different from a traditional browser cookie.
3. Who Is Responsible for Hawi Cookies?
For first-party cookies set directly through Hawi's Services, the responsible organisation is:
Hawi Inc
Trading as Hawi Agents
[INSERT REGISTERED ADDRESS]
Privacy contact: [INSERT PRIVACY EMAIL]
Some cookies and similar technologies are operated by third parties that provide services to Hawi.
Those third parties may act as processors, independent controllers or otherwise have responsibilities under applicable data-protection law depending on the technology and circumstances.
4. Legal Framework
Our use of cookies and similar technologies is intended to comply with applicable laws, including, where relevant:
- the UK Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”);
- the UK General Data Protection Regulation (“UK GDPR”);
- the Data Protection Act 2018;
- amendments made by applicable UK data legislation;
- and equivalent European or other privacy and electronic-communications laws where they apply.
Where consent is required, Hawi will seek consent before activating the relevant non-essential cookie or similar technology.
Where consent is not legally required because an applicable exemption applies, we may use the technology without consent but will still provide appropriate information about it.
5. Strictly Necessary Cookies
Certain technologies are necessary for the Services to operate correctly or securely.
These may be used without optional cookie consent where permitted by applicable law.
Strictly necessary technologies may be used to:
- authenticate users;
- keep users signed in;
- maintain secure sessions;
- prevent account takeover;
- protect against cross-site request forgery;
- maintain security controls;
- remember privacy choices;
- process payments requested by you;
- detect or prevent fraudulent payments;
- route traffic;
- distribute server load;
- maintain essential application state;
- enforce Account and Workspace permissions;
- support account recovery;
- maintain the integrity of a transaction;
- prevent duplicate operations;
- and provide functionality specifically requested by the user.
Blocking strictly necessary cookies may prevent important parts of Hawi from working.
6. Authentication and Session Technologies
Hawi operates authenticated Accounts, Workspaces and dashboards.
Authentication technologies may therefore be used to:
- identify an authenticated session;
- verify that a request belongs to the correct signed-in user;
- refresh an authenticated session;
- prevent unauthorised Account access;
- maintain Account and Workspace context;
- enforce access controls;
- protect administrative pages;
- and securely terminate sessions when you sign out.
Depending on Hawi's current technical implementation, authentication identifiers may be stored using secure first-party cookies or other protected browser storage.
Authentication cookies should, where technically appropriate, use safeguards such as:
- Secure;
- HttpOnly;
- appropriate SameSite settings;
- scoped domains and paths;
- expiry controls;
- and cryptographically secure session identifiers.
7. Supabase and Authentication Infrastructure
Hawi uses Supabase infrastructure for portions of its application and data services.
Where Hawi uses cookie-based Supabase authentication, authentication cookies may use names following patterns such as:
sb-<project-reference>-auth-token
or related/split variants generated by the authentication implementation.
These technologies may be used to:
- authenticate a user;
- maintain a logged-in session;
- refresh authentication credentials;
- and securely associate requests with the correct Account.
The exact format of a cookie may vary depending on the version and authentication configuration in use.
Authentication cookies are treated as strictly necessary where they are required to provide the signed-in service requested by the user.
8. Security and Fraud-Prevention Technologies
Hawi may use cookies and similar technologies to protect:
- users;
- Accounts;
- payments;
- Workspaces;
- Agents;
- APIs;
- Marketplace activity;
- and Hawi infrastructure
from fraud, abuse and security threats.
Security technologies may help identify:
- automated attacks;
- suspicious login behaviour;
- account takeover attempts;
- abusive traffic;
- fraudulent payment attempts;
- repeated failed authentication;
- bot activity;
- suspicious transaction patterns;
- malicious requests;
- or attempts to circumvent security controls.
Where a security or fraud-prevention technology is strictly necessary to securely provide a service requested by you, it may be used without optional consent to the extent permitted by law.
9. Payment Cookies
Hawi uses third-party payment services, including Stripe, to support payment functionality.
When you:
- subscribe to a Plan;
- purchase Credits;
- purchase Voice Units;
- purchase additional Seats;
- purchase a Marketplace product;
- enable eligible automatic recharge;
- make another payment;
- or access certain checkout functionality,
Stripe may set or access cookies and similar technologies.
These may be used for:
- fraud detection;
- payment security;
- authentication;
- checkout functionality;
- payment-session continuity;
- preventing duplicate or suspicious payment activity;
- and providing eligible payment features such as saved checkout information.
10. Stripe Fraud-Prevention Cookies
Depending on the payment configuration in use, Stripe may use technologies including:
__stripe_mid
Provider: Stripe
Purpose: Fraud detection and prevention, including helping assess the risk associated with a payment attempt.
Typical duration: approximately 1 year.
Category: Strictly necessary / security and fraud prevention where required for payment security.
__stripe_sid
Provider: Stripe
Purpose: Fraud detection and prevention during a payment session.
Typical duration: approximately 30 minutes.
Category: Strictly necessary / security and fraud prevention where required for payment security.
Stripe may also use additional technologies depending on the payment products enabled, including browser storage, payment-session identifiers and technologies associated with Stripe Checkout, Stripe Elements, Radar or Link.
Stripe may change its technologies over time.
11. Stripe Link and Checkout Technologies
If Hawi enables Stripe Link, embedded checkout or related Stripe functionality, Stripe may use additional identifiers such as:
- pay_sid;
- __Host-LinkSession;
- link.auth_session_client_secret;
- elements_session;
- m;
- or similar technologies.
Their purpose may include:
- authentication;
- remembering a user's checkout state;
- fraud prevention;
- enabling faster checkout;
- and measuring the technical operation of Stripe's payment products.
Not every Stripe identifier listed in this Policy will necessarily be used during every Hawi visit or transaction.
The cookies activated depend on the Stripe products and checkout flow being used.
12. Cookie Consent and Preference Technologies
Hawi may store an essential preference record to remember whether you:
- accepted optional cookies;
- rejected optional cookies;
- selected individual cookie categories;
- or changed a previous preference.
For example, Hawi may use a first-party identifier similar to:
hawi_cookie_consent
or
hawi_cookie_preferences
The exact technical identifier may change as our consent-management system evolves.
A consent-preference record may store information such as:
- your selected categories;
- the time of the choice;
- the version of the cookie notice;
- and an anonymous consent identifier.
The purpose is to remember and respect your privacy choices.
A cookie used solely to remember your cookie preferences may be considered necessary for managing the choice you requested.
13. Preference Cookies
With consent where required, Hawi may use preference technologies to remember choices such as:
- interface settings;
- language;
- accessibility preferences;
- layout options;
- dismissed notices;
- dashboard preferences;
- preferred Workspace;
- selected viewing options;
- or similar convenience settings.
Some preference technologies may qualify as strictly necessary where they are essential to deliver functionality specifically requested by you.
Others will only be used after consent where required.
14. Local Storage and Session Storage
Some Hawi functionality may use browser localStorage or sessionStorage.
These technologies may store information such as:
- authentication state;
- temporary application state;
- privacy preferences;
- user-interface settings;
- unsaved form state;
- temporary workflow information;
- security state;
- checkout state;
- or other information necessary to operate the web application.
sessionStorage generally remains until the relevant browser tab or session is closed.
localStorage may remain until:
- it expires through application logic;
- you clear it;
- or Hawi removes it.
Where PECR or equivalent law applies, these technologies are treated according to their purpose rather than being treated differently simply because they are not traditional cookies.
15. Functional Cookies
Functional cookies help provide enhanced features that may not be essential to the core operation of Hawi.
They may support:
- enhanced user-interface behaviour;
- richer embedded components;
- convenience features;
- support widgets;
- media functionality;
- or remembered optional preferences.
Where a functional technology is not strictly necessary, Hawi will obtain consent before activating it where required.
If you refuse functional cookies, some optional features may not operate as intended.
16. Analytics Technologies
Hawi may use analytics technologies to understand how the Services perform and how users interact with them.
Analytics may help us understand matters such as:
- page usage;
- navigation;
- general feature adoption;
- technical performance;
- load time;
- errors;
- aggregate usage patterns;
- and whether product changes improve the Services.
Hawi does not treat ordinary product analytics as strictly necessary merely because the information would be useful to us.
Where consent is required, analytics technologies will remain disabled until you consent.
17. Privacy-Preserving Analytics
Where an analytics service can operate without accessing or storing information on your device, the cookie rules may apply differently.
However, where an analytics service places or accesses device information covered by applicable cookie or storage/access rules, Hawi will classify the technology according to its actual operation.
We will not describe tracking as “anonymous” merely as a way to avoid applicable consent requirements.
18. Advertising and Behavioural Tracking
Hawi does not classify advertising or behavioural-tracking technologies as strictly necessary.
If Hawi introduces technologies for:
- targeted advertising;
- retargeting;
- cross-site behavioural profiles;
- advertising attribution;
- social-media advertising pixels;
- or personalised advertising,
they will be placed in an optional category and will not be activated before consent where consent is required.
If Hawi does not use advertising technologies, rejecting this category will have no effect on core Services.
19. Social-Media Technologies
Hawi may provide links to external social-media services.
A normal external link does not necessarily cause the social-media provider to set a cookie on Hawi.
However, embedded social-media content, buttons, pixels or widgets can allow another provider to receive information about your device or visit.
Where such technologies are non-essential, Hawi will seek consent where required before loading them.
20. Embedded Third-Party Content
Some pages may contain content or functionality supplied by another company.
Examples can include:
- videos;
- interactive tools;
- payment interfaces;
- support interfaces;
- maps;
- forms;
- or other embedded functionality.
The third party may set cookies when its content is loaded.
Where the technology is optional, Hawi may require you to consent before the embedded content is loaded.
21. Third-Party Integrations
Hawi allows users to connect third-party services to their Accounts.
Examples can include:
- email services;
- calendars;
- CRM platforms;
- productivity services;
- commerce services;
- financial services;
- communications platforms;
- and other business tools.
Connecting an Integration can involve being redirected to the provider's own website for authentication.
When you visit that third-party website, its own cookies and privacy policy apply.
A cookie set directly by the third party on the third party's own website is controlled according to that provider's rules.
22. OAuth and Connection Flows
Third-party integrations may use OAuth or another authorisation mechanism.
During an OAuth flow:
- Hawi may create temporary security state;
- you may be redirected to the third party;
- the provider may use its own authentication cookies;
- the provider returns you to Hawi;
- Hawi verifies the returned authorisation state;
- and the connection is created if successful.
Temporary state used to prevent tampering or cross-site request forgery may be considered strictly necessary to provide the connection requested by you.
23. Vercel Hosting and Deployment Technologies
Hawi uses Vercel for portions of its application hosting and deployment infrastructure.
Vercel may use technical infrastructure necessary to:
- deliver application content;
- secure deployment environments;
- manage protected previews;
- route requests;
- or protect infrastructure.
Certain non-public preview or administrative deployments may use Vercel authentication technologies that ordinary production visitors do not encounter.
For example, protected Vercel previews may use a cookie such as:
_vercel_sso_nonce
for temporary authentication/security purposes.
A cookie used only in a protected development or preview environment does not necessarily appear on Hawi's normal public production website.
24. Agent Operation Does Not Automatically Mean Browser Tracking
Hawi Agents may use external services server-to-server.
For example, an Agent may interact with:
- an email provider;
- model provider;
- telephone provider;
- database;
- commerce system;
- or API.
The fact that Hawi uses a provider in the backend does not necessarily mean that provider places cookies on your browser.
This Cookie Policy focuses on technologies that store information on or access information from your device.
Our Privacy Policy explains broader processing involving service providers.
25. First-Party and Third-Party Cookies
A first-party cookie is generally set by the Hawi domain that you are visiting.
A third-party cookie is generally associated with another organisation or domain.
Third-party technologies can be used for purposes including:
- payments;
- fraud prevention;
- embedded functionality;
- authentication;
- analytics;
- and integrations.
The distinction between first-party and third-party does not itself determine whether consent is required.
The purpose and legal basis of the technology are what matter.
26. Session and Persistent Cookies
Cookies may be:
Session cookies
These normally expire when you close your browser or after a relatively short period.
They may be used for:
- authentication;
- security;
- temporary application state;
- or transaction continuity.
Persistent cookies
These remain after the browser is closed until:
- their expiry date;
- they are deleted;
- or the application removes them.
Persistent cookies may be used to remember:
- privacy choices;
- recognised security state;
- login-related information;
- or optional preferences.
27. How Long Do We Keep Cookies?
We aim to keep cookie durations proportionate to their purpose.
Different technologies therefore have different durations.
For example:
- a temporary security cookie may last only minutes;
- a session identifier may last for a browser session;
- an authentication refresh mechanism may remain for the permitted login period;
- a consent preference may remain for several months;
- and a fraud-prevention identifier may remain longer to recognise suspicious repeated activity.
We periodically review whether retention periods remain appropriate.
28. Our Cookie Register
The following table describes the principal categories and technologies that may be relevant to Hawi.
| Cookie / technology | Provider | Category | Purpose | Typical duration |
|---|---|---|---|---|
| hawi_cookie_consent / equivalent | Hawi | Strictly necessary | Remembers cookie consent choices | Up to approximately 12 months |
| hawi_cookie_preferences / equivalent | Hawi | Strictly necessary / preferences | Stores selected privacy categories and settings | Up to approximately 12 months |
| sb-<project-reference>-auth-token or related variants, where used | Hawi / Supabase | Strictly necessary | Authentication and session management | Session/authentication lifetime |
| Application session identifiers | Hawi | Strictly necessary | Keeps authenticated users securely signed in | Session or configured login period |
| Security / CSRF state | Hawi | Strictly necessary | Protects requests and connection flows | Usually session or short-lived |
| OAuth state | Hawi / relevant provider | Strictly necessary | Protects third-party connection authorisation | Short-lived |
| __stripe_mid | Stripe | Strictly necessary / fraud prevention | Payment fraud prevention and risk assessment | Approximately 1 year |
| __stripe_sid | Stripe | Strictly necessary / fraud prevention | Payment-session fraud prevention | Approximately 30 minutes |
| m or equivalent, where used | Stripe | Strictly necessary / fraud prevention | Fraud and bot risk assessment | Varies / session depending implementation |
| Stripe Link identifiers, if Link is enabled | Stripe | Functional / authentication / payment | Optional faster checkout and authentication functionality | Varies |
| _vercel_sso_nonce, protected previews only | Vercel | Strictly necessary | Secures access to protected deployment environments | Approximately 1 hour / temporary |
| Analytics identifiers, if enabled | Hawi / analytics provider | Analytics | Product and website measurement | As shown in Cookie Settings |
| Functional third-party identifiers, if enabled | Relevant provider | Functional | Optional embedded functionality | Provider-specific |
| Advertising identifiers, if enabled | Relevant provider | Advertising | Advertising measurement or personalisation | Provider-specific |
Important: the exact cookie name may change because of:
- provider updates;
- software versions;
- browser limitations;
- security improvements;
- configuration changes;
- or a change in the service being used.
Hawi should update this register when a material new technology is introduced.
29. Cookie Banner
Where required, Hawi will provide a cookie or privacy preference interface.
Before non-essential cookies are activated, the interface should provide clear options such as:
Accept All
Reject Non-Essential
Manage Preferences
The design should not make refusal materially more difficult than acceptance.
30. No Consent by Silence
Where consent is required, Hawi will not treat the following alone as valid consent:
- simply visiting the site;
- scrolling;
- continuing to browse;
- closing the banner;
- inactivity;
- or a pre-selected checkbox.
Consent should involve a clear positive choice.
31. Granular Cookie Choices
Where appropriate, you may be able to choose separately whether to enable categories such as:
- Strictly Necessary;
- Functional;
- Analytics;
- Advertising.
Strictly necessary technologies cannot normally be disabled through Hawi's preference centre because disabling them may prevent the requested Service from operating.
You can still block them using your browser, but doing so may break the application.
32. Rejecting Cookies
Choosing Reject Non-Essential should prevent non-essential cookie categories from being activated where technically required by law.
Rejecting optional cookies should not prevent you from accessing core Hawi functionality merely because you exercised your privacy choice.
Some optional features may nevertheless be unavailable if they specifically depend on a technology you rejected.
33. Withdrawing Consent
You may withdraw consent to non-essential cookies at any time.
Where implemented, you can do this by selecting:
Cookie Settings
or a similarly named privacy control available on the Hawi website.
Withdrawing consent should be as easy as giving consent.
Withdrawal applies going forward.
It does not make processing that lawfully occurred before withdrawal unlawful.
34. Changing Your Preferences
You may change your preference from:
- accepted to rejected;
- rejected to accepted;
- or modify individual categories.
The most recent valid selection should generally take precedence over an earlier choice associated with the same device or browser.
35. Consent Records
Hawi may maintain a record demonstrating that a privacy choice was made.
A consent record may include:
- an anonymous consent identifier;
- preference categories;
- policy or banner version;
- date and time;
- and limited technical information required to demonstrate or implement the choice.
Consent records may be retained for an appropriate period to:
- prove compliance;
- respect your preferences;
- respond to regulatory enquiries;
- and investigate disputes concerning consent.
36. Renewing Cookie Consent
Hawi may ask you to make a new cookie choice where:
- we materially change our cookie use;
- new purposes are introduced;
- new third parties are introduced;
- a previous preference can no longer reliably be identified;
- the consent has become stale;
- or applicable law or regulatory guidance requires renewed consent.
37. Browser Controls
Most browsers allow you to control cookies.
Depending on your browser, you may be able to:
- view cookies;
- delete cookies;
- clear site data;
- block specific websites from using cookies;
- block third-party cookies;
- automatically delete cookies when you close the browser;
- or prevent all cookie storage.
Browser settings are separate from Hawi's own Cookie Settings.
38. What Happens If You Block All Cookies?
Blocking all cookies may cause important Hawi functionality to stop working.
For example, you may be unable to:
- sign in;
- remain signed in;
- maintain a secure Account session;
- complete checkout;
- connect certain services;
- remember privacy settings;
- or access authenticated dashboards.
For this reason, disabling optional cookies through Hawi's Cookie Settings is generally preferable to blocking all cookies when you still want to use the Services.
39. Private or Incognito Browsing
Private or incognito browsing may cause cookies or browser storage to be deleted when the browsing session ends.
However, private browsing does not necessarily prevent:
- websites from receiving your IP address;
- service providers from processing requests;
- network operators from seeing traffic;
- or online services from receiving information you actively provide.
Private browsing should therefore not be understood as complete anonymity.
40. Do Not Track
Some browsers send a “Do Not Track” signal.
There is not a single universally implemented technical standard governing all responses to these signals.
Where applicable law requires recognition of a particular browser signal, Hawi will respond as legally required.
Otherwise, your Hawi Cookie Settings provide the primary mechanism for controlling optional technologies.
41. Global Privacy Control
Where technically supported and legally applicable, Hawi may recognise browser-based privacy preference signals such as Global Privacy Control.
A recognised signal may affect optional tracking or advertising technologies.
Where there is a conflict between stored consent and a more recent recognised privacy signal, Hawi may apply the more privacy-protective or more recent instruction where appropriate.
42. Cookies on Shared Devices
A cookie is generally associated with a browser or device, not necessarily with one specific human being.
If several people use the same browser:
- one person's cookie choice may affect another user;
- one user may change the stored preference;
- and signing out is important when using a shared device.
We recommend that users of shared computers sign out of Hawi after use.
43. Cookie Data and Personal Data
Some cookie data may constitute personal data.
Examples can include:
- persistent identifiers;
- Account-linked session information;
- IP addresses;
- device information;
- usage information;
- and fraud-prevention signals.
Where cookie information is personal data, our Privacy Policy explains matters including:
- purposes of processing;
- lawful bases;
- sharing;
- international transfers;
- retention;
- and your rights.
44. International Data Transfers
Some third-party providers may process cookie-related information in countries outside the United Kingdom or European Economic Area.
Where required, Hawi will use appropriate safeguards for international transfers of personal data.
Those safeguards may include:
- adequacy regulations or decisions;
- approved contractual clauses;
- the UK International Data Transfer Agreement;
- an appropriate UK Addendum;
- or another legally recognised transfer mechanism.
Further information is available in our Privacy Policy.
45. Third-Party Cookie Policies
Third-party providers maintain their own privacy and cookie information.
Where relevant to the technology you use, you should review the privacy information provided by organisations such as:
- Stripe;
- Supabase;
- Vercel;
- and any third-party service you connect to Hawi.
A provider may change its technology independently of Hawi.
46. Provider Changes
Third-party services periodically:
- add cookies;
- rename cookies;
- change durations;
- change domains;
- modify security technology;
- or replace browser-storage mechanisms.
We periodically review our providers and update this Policy where changes materially affect users.
A minor technical change to an identifier that does not materially change its purpose may not result in an immediate Policy amendment.
47. No Hidden Tracking Exemption
Hawi will not intentionally categorise a technology as “strictly necessary” solely because:
- it benefits our business;
- it improves marketing;
- it provides analytics;
- it makes advertising more effective;
- or we would prefer to use it.
The strictly necessary category is reserved for technologies that fall within the relevant legal exemption or are otherwise permitted without optional consent.
48. Analytics and Consent
If Hawi uses device-based analytics that require consent, those analytics should not activate until consent has been obtained.
This includes analytics code that stores or accesses device information even where the resulting statistics are later aggregated.
49. Advertising Consent
Advertising and cross-site behavioural tracking technologies, if ever introduced, must be treated as optional unless an applicable law expressly permits otherwise.
A user should be able to use the principal Hawi service without being forced to agree to behavioural advertising merely as a condition of accessing unrelated core functionality.
50. Sensitive Information
Hawi does not intend to use advertising cookies to build advertising profiles based on highly sensitive information processed through users' Agents or Workspaces.
In particular, information contained within private:
- emails;
- files;
- Agent conversations;
- telephone calls;
- financial workflows;
- Workspace documents;
- or private integrations
should not be repurposed into third-party behavioural advertising merely because the information is processed through Hawi.
Any materially different practice would require appropriate disclosure and legal analysis.
51. Agent and Workspace Data
Cookies used in a user's browser are different from data processed inside Hawi's backend when an Agent performs a task.
For example:
- an Agent reading an authorised email;
- an Agent creating a calendar entry;
- an Agent making an authorised call;
- or an Agent using an API
may involve personal-data processing but may not involve storing a cookie on the user's device.
Those activities are covered primarily by our Privacy Policy and Terms rather than this Cookie Policy.
52. Mobile Applications
If Hawi offers a mobile application, similar storage and access rules may apply to technologies used within the application.
These can include:
- app storage;
- device identifiers;
- SDKs;
- authentication tokens;
- advertising identifiers;
- and analytics technologies.
Where required, equivalent controls and disclosures will be provided within the application.
53. Children
Hawi's general Services are not intended to be used by persons who do not satisfy the applicable minimum age requirements stated in our Terms.
We do not intentionally use advertising cookies to profile children.
54. Security of Cookie Information
We use reasonable technical and organisational measures to protect information associated with cookies and browser storage.
Depending on the technology, measures may include:
- encryption;
- secure transport;
- limited retention;
- secure cookie flags;
- server-side access controls;
- role-based access;
- session revocation;
- anti-CSRF protection;
- audit controls;
- and monitoring for suspicious activity.
No security system can guarantee absolute protection.
55. Cookie Audits
Hawi should periodically audit the Services to identify:
- what cookies and similar technologies are in use;
- who provides them;
- their purpose;
- whether they access personal data;
- their duration;
- whether they are first-party or third-party;
- whether they are strictly necessary;
- whether consent is required;
- whether they are blocked before consent where required;
- and whether this Policy remains accurate.
Technologies no longer reasonably required should be removed where appropriate.
56. Changes to This Cookie Policy
We may update this Cookie Policy from time to time.
Reasons may include:
- legal changes;
- regulatory guidance;
- technical changes;
- introduction of new providers;
- changes to payments;
- changes to authentication;
- new analytics tools;
- security improvements;
- or changes to Hawi functionality.
When we make a material change, we may:
- update the “Last Updated” date;
- notify users;
- display a notice;
- or ask users to renew their cookie preferences where appropriate.
57. Relationship with Our Privacy Policy
This Cookie Policy focuses on information stored on or accessed from a user's device.
Our Privacy Policy provides broader information about how Hawi processes personal data.
If a technology described in this Policy involves personal data, the Privacy Policy also applies.
58. Your Data-Protection Rights
Depending on applicable law and the circumstances, you may have rights relating to personal data associated with cookies, including rights to:
- access personal data;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to certain processing;
- withdraw consent;
- obtain certain portable data;
- and complain to a supervisory authority.
These rights are explained in greater detail in our Privacy Policy.
Not every right applies in every circumstance.
59. UK Information Commissioner
If you are in the United Kingdom and believe we have not handled your privacy rights appropriately, you may have the right to complain to the Information Commissioner's Office (“ICO”).
We encourage you to contact Hawi first so that we have an opportunity to investigate and resolve your concern.
60. How to Contact Us
For questions about cookies, privacy choices or this Cookie Policy, contact:
Hawi Inc
Trading as Hawi Agents
Registered office:
[INSERT REGISTERED ADDRESS]
Privacy email:
[INSERT PRIVACY EMAIL]
Support email:
[INSERT SUPPORT EMAIL]
Website:
[INSERT FINAL PRODUCTION DOMAIN]
Schedule 1 — Cookie Category Summary
Strictly Necessary
Consent required: Normally no, where a valid statutory exemption applies.
Examples:
- authentication;
- security;
- cookie preferences;
- fraud prevention;
- checkout security;
- traffic routing;
- essential application state.
These cannot generally be disabled through Hawi Cookie Settings without affecting core functionality.
Functional
Consent required: Yes where required by applicable law and no exemption applies.
Examples:
- enhanced interface preferences;
- optional embeds;
- optional support features;
- richer third-party functionality.
Analytics
Consent required: Yes where the technology falls within applicable consent requirements and no exemption applies.
Examples:
- visitor measurement;
- feature usage statistics;
- performance analytics;
- conversion analytics.
Advertising
Consent required: Yes where required by law.
Examples:
- behavioural advertising;
- retargeting;
- social advertising pixels;
- cross-site advertising measurement.
Advertising is not treated as essential to access Hawi's core Services.
Schedule 2 — Cookie Consent Standard
Hawi's cookie interface should be configured so that:
- Strictly necessary cookies may operate from the beginning where legally permitted.
- Analytics cookies default to off before consent where consent is required.
- Advertising cookies default to off.
- Optional functional cookies default to off where consent is required.
- There are no pre-ticked optional categories.
- “Accept All” does not appear without a comparably accessible rejection choice.
- “Reject Non-Essential” is straightforward to select.
- Closing the banner does not count as consent.
- Continuing to browse does not count as consent.
- Consent choices are recorded.
- A user can later reopen Cookie Settings.
- Withdrawing consent is no more difficult than giving it.
- Scripts requiring consent are technically prevented from loading before consent.
- Third parties are identified where required.
- Consent is requested again where material purposes change.
Schedule 3 — Technical Implementation Requirements
To keep this Policy accurate, Hawi's production website should maintain a live cookie inventory covering:
- cookie name;
- provider;
- domain;
- path;
- purpose;
- category;
- expiration;
- first-party or third-party status;
- Secure status;
- HttpOnly status where applicable;
- SameSite configuration;
- whether personal data is involved;
- consent requirement;
- and the consent category controlling it.
Any analytics, advertising or non-essential script should be tested to confirm that it does not issue network calls, write to local storage, set cookies or read relevant device data before the required consent has been obtained.
Schedule 4 — Third-Party Technology Summary
Supabase
Hawi may use Supabase for authentication, database, storage or related application services.
Where browser authentication technologies are used, they are primarily used to provide authenticated functionality and security.
Stripe
Hawi uses Stripe in connection with payment functionality.
Stripe may use cookies and related technologies for:
- payment processing;
- fraud detection;
- authentication;
- checkout;
- and payment security.
Stripe technologies used can vary according to the Stripe products enabled.
Vercel
Hawi uses Vercel for application infrastructure and deployment.
Vercel may process technical request information and may use cookies for specific services such as protected deployment access.
Preview-environment cookies do not necessarily apply to normal users of Hawi's production service.
Connected Third-Party Services
Where you deliberately connect a third-party service to Hawi, you may be redirected to that provider.
Cookies set while you are visiting the provider's own domain are governed by that provider's policies and settings.
Schedule 5 — Important User Choices
You can control non-essential technologies through Hawi's Cookie Settings where available.
You may also control cookies through your browser.
Remember:
- rejecting analytics should not prevent ordinary account access;
- rejecting advertising should not prevent ordinary account access;
- essential authentication cookies may be required to remain signed in;
- payment-security technologies may be required to process a requested payment safely;
- and third-party provider websites may operate their own independent cookies when you visit them.
END OF COOKIE POLICY